Among European countries, Portugal ranked 19th for the frequency with which customers were affected by malicious cyber activity during the first half of 2026.
In its seventh edition, the report highlights the growing role of artificial intelligence in the cybersecurity landscape, with AI used by both attackers and security teams to speed up processes and operate at scale.
User intentions
For cyber criminals, the technology makes it possible to discover vulnerabilities, analyse information, and adapt attacks more quickly.
Meanwhile, security teams use AI to identify and investigate threats and respond more efficiently.
Despite these developments, compromised accounts and stolen credentials remain among the main ways attackers gain access to organisations.
Therefore, identity protection has been identified as an area of concern, with phishing accounting for 23 percent of the intrusions recorded in 2026.
Microsoft advises organisations to reinforce safeguards around their digital identities, particularly for critical accounts, to reduce the chances of an initial breach and prevent attacks from spreading further.
Furthermore, government bodies and public services continue to attract significant attention from cyber attackers, accounting for 27 percent of the activity recorded this year.
Target sector
The sector is considered an attractive target because public organisations hold sensitive information and provide essential services.
They are also connected to wider networks involving public bodies, technology companies, service providers and operators of critical infrastructure.
Pedro Soares, National Security Director at Microsoft Portugal, said the cyber security landscape had entered a new phase in which preventing attacks alone was no longer enough.
He added that organisations must also be able to respond quickly, protect their digital identities and keep essential operations running when incidents occur, explaining that resilience has become increasingly important to both security and competitiveness.
The report similarly warns that cyber threats are becoming faster, more interconnected and harder to contain.
In this environment, resilience involves more than recovering after an attack.
According to Microsoft, it also means preparing for incidents that can spread quickly across multiple organisations and require coordinated responses to keep essential services running.














Follow us on social media